BACKGROUND OF THE INVENTION
Technical Field
[0001] The present invention relates generally to techniques for enabling a Web site origin
server to obtain content delivery services from a third party service provider on
an as-needed basis.
Description of the Related Art
[0002] Today's Web sites are a double-edged sword. They present enterprises with the opportunity
for both resounding success and costly, dramatic failure. The possibility for either
scenario to occur is chiefly due to the Internet's open design. Indeed, the ability
to reach a global community of customers and partners via the Web comes with many
risks. The open design means that enterprises must expose themselves by opening a
public entry-point to get the global reach they need. Couple that with the inherent
weaknesses of centralized infrastructure and there is a recipe for failure. Indeed,
a growing number of threats can bring a site down daily. These threats include hacker
attacks, viruses, Internet worms, content tampering and Denial of Service (DoS) attacks.
Moreover, the site's popularity itself can generate "flash crowds" that overload the
capabilities of the site's origin server(s). Any one of these events can produce unpredictable
site disruptions that impede revenue operations, dilute brand investments, hamper
productivity and reduce goodwill and reputation.
[0003] A content provider can ameliorate these problems by outsourcing its content delivery
requirements to a content delivery network (a "CDN"). A content delivery network is
a collection of content servers and associated control mechanisms that offload work
from Web site origin servers by delivering content on their behalf to end users. A
well-managed CDN achieves this goal by serving some or all of the contents of a site's
Web pages, thereby reducing the customer's infrastructure costs while enhancing an
end user's browsing experience from the site. In operation, the CDN uses a request
routing mechanism to locate a CDN content server close to the client to serve each
request directed to the CDN, where the notion of "close" is based, in part, on evaluating
results of network traffic tests.
[0004] While content delivery networks provide significant advantages, some content providers
prefer to maintain primary control over their Web site infrastructure or may not wish
to pay for the cost of fully-provisioned CDN services. As a result, the site remains
exposed to the myriad of potential security and flash crowds that may bring the site
down at any time.
[0005] EP 0 817 444 (Sun Microsystems) is directed to a system for name resolution in which requests
to a given service or domain name are resolved to an appropriate IP address based
on information about the sender (e.g., their geographic location), information about
the recipient (e.g., type of service requested) or other information. (Abstract.)
Further it is stated that if one valid destination fails or is overloaded, the unavailable
destination can be administratively disabled in the name resolver's internal tables.
(Col. 3, lines 9-13.)
[0007] It would be highly desirable to provide a content provider the ability to receive
"on demand" use of a CDN to provide an additional layer of protection to ensure business
continuity of an enterprise Web site. The present invention addresses this need.
BRIEF SUMMARY OF THE INVENTION
[0008] The invention is defined by the subject made of the independent claims.
[0009] Preferably wherein additional DNS queries are redirected to the CDN domain until
it is determined that the given event has ended.
[0010] Preferably wherein the given content is an object, or a markup language page having
a set of one or more embedded objects.
[0011] Preferably wherein the given event is an origin server failure.
[0012] Preferably wherein the given event is an occurrence of excess demand at a site hosted
on the origin server.
[0013] Preferably wherein the given event is any of: (i) a receipt of a request for content
that cannot be served from the origin server, (ii) excess demand for streaming content
on a Website hosted by the origin server, (iii) excess traffic originating from a
certain geography or network; (iv) excess latency at the site as perceived by network
agents, and (v) a Denial of Service (DOS) attack.
[0014] Preferably, wherein the CDN further provides a traffic management service, comprising:
responsive to the end user's name server making a query to the content provider domain,
and when the given event has not occurred, resolving the query to an IP address associated
with an origin server.
[0015] Preferably, wherein the origin server is one of a set of mirrored origin servers.
[0016] Preferably, wherein the dynamic modification of the DNS record is made in a name
server associated with the origin server.
[0017] Preferably, wherein the dynamic modification of the DNS record is made in a name
server associated with the CDN.
[0018] Preferably wherein the DNS record is dynamically modified using a CNAME.
[0019] Preferably wherein the name server redirects additional DNS queries to the CDN domain
until determining that the given event has ended.
[0020] Preferably wherein the given content is an object, or a markup language page having
a set of one or more embedded objects.
[0021] Preferably wherein the given event is any of: (i) origin server failure, (ii) an
occurrence of excess demand at a site hosted on the origin server, (iii) a receipt
of a request for content that cannot be served from the origin server, (iv) excess
demand for streaming content on a Website hosted by the origin server, (v) excess
traffic originating from a certain geography or network; (vi) excess latency at the
site as perceived by network agents, and (vii) a Denial of Service (DOS) attack.
[0022] Preferably, wherein the name server is a name server associated the origin server.
[0023] Preferably, wherein the name server is a CDN name server.
[0024] Preferably, wherein the name server dynamically modifies the DNS record using a CNAME.
[0025] The foregoing has outlined some of the more pertinent features of the present invention.
These features should be construed to be merely illustrative. Many other beneficial
results can be attained by applying the disclosed invention in a different manner
or by modifying the invention as will be described.
BRIEF DESCRIPTION OF THE DRAWINGS
[0026]
Figure 1 is a block diagram of a known content delivery network in which the present
invention may be implemented;
Figure 2 is a simplified block diagram illustrating how site insurance functionality
is provided according to the present invention;
Figure 3 is a flowchart illustrating how the site insurance is triggered upon determination
of a given event at the origin server; and
Figure 4 illustrates a global traffic management system in which the site insurance
functionality may be integrated according to an embodiment of the present invention.
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENT
[0027] By way of background, it is known in the prior art to deliver digital content (e.g.,
HTTP content, streaming media and applications) using an Internet content delivery
network (CDN). A CDN is a network of geographically-distributed content delivery nodes
that are arranged for efficient delivery of content on behalf of third party content
providers. Typically, a CDN is implemented as a combination of a content delivery
infrastructure, a request-routing mechanism, and a distribution infrastructure. The
content delivery infrastructure usually comprises a set of "surrogate" origin servers
that are located at strategic locations (e.g., Internet network access points, Internet
Points of Presence, and the like) for delivering content to requesting end users.
The request-routing mechanism allocates servers in the content delivery infrastructure
to requesting clients in a way that, for web content delivery, minimizes a given client's
response time and, for streaming media delivery, provides for the highest quality.
The distribution infrastructure consists of on-demand or push-based mechanisms that
move content from the origin server to the surrogates. An effective CDN serves frequently-accessed
content from a surrogate that is optimal for a given requesting client. In a typical
CDN, a single service provider operates the request-rooters, the surrogates, and the
content distributors. In addition, that service provider establishes business relationships
with content publishers and acts on behalf of their origin server sites to provide
a distributed delivery system.
[0029] The request-routing mechanism 104 allocates servers 102 in the content delivery infrastructure
to requesting clients. The distribution infrastructure consists of on-demand or push-based
mechanisms that move content from the origin server to the surrogates. A CDN service
provider (CDNSP) may organize sets of surrogate origin servers as a group or so-called
"region." In this type of arrangement, a CDN region 106 typically comprises a set
of one or more content servers that share a common back-end network, e.g., a LAN,
and that are located at or near an Internet access point. Thus, for example, a typical
CDN region may be co-located within an Internet Service Provider (ISP) Point of Presence
(PoP) 108. A representative CDN content server is a Pentium-based caching appliance
running an operating system (e.g., Linux, Windows NT, Windows 2000) and having suitable
RAM and disk storage for CDN applications and content delivery network content (e.g.,
HTTP content, streaming media and applications). Such content servers are sometimes
referred to as "edge" servers as they are located at or near the so-called outer reach
or "edge" of the Internet. The CDN typically also includes network agents 109 that
monitor the network as well as the server loads. These network agents are typically
co-located at third party data centers or other locations. Mapmaker software 107 receives
data generated from the network agents and periodically creates maps that dynamically
associate IP addresses (e.g., the IP addresses of client-side local name servers)
with the CDN regions.
[0030] Content may be identified for delivery from the CDN using a content migrator or rewrite
tool 106 operated, for example, at a participating content provider server. Tool 106
rewrites embedded object URLs to point to the CDNSP domain. A request for such content
is resolved through a CDNSP-managed DNS to identify a "best" region, and then to identify
an edge server within the region that is not overloaded and that is likely to host
the requested content. Instead of using content provider-side migration (e.g., using
the tool 106), a participating content provider may simply direct the CDNSP to serve
an entire domain (or subdomain) by a DNS directive (e.g., a CNAME). In either case,
the CDNSP may provide object-specific metadata to the CDN content servers to determine
how the CDN content servers will handle a request for an object being served by the
CDN. Metadata, as used herein, refers to a set of control options and parameters for
the object (e.g., coherence information, origin server identity information, load
balancing information, customer code, other control codes, etc.), and such information
may be provided to the CDN content servers via a configuration file, in HTTP headers,
or in other ways. The Uniform Resource Locator (URL) of an object that is served from
the CDN in this manner does not need to be modified by the content provider. When
a request for the object is made, for example, by having an end user navigate to a
site and select the URL, a customer's DNS system directs the name query (for whatever
domain is in the URL) to the CDNSP DNS request routing mechanism. A representative
CDN DNS request routing mechanism is described, for example, in
U.S. Patent No. 6,108,703.
[0031] Once an edge server is identified, the browser passes the object request to the server,
which applies the metadata supplied from a configuration file or HTTP response headers
to determine how the object will be handled.
[0032] As also seen in Figure 1, the CDNSP may operate a metadata transmission system 116
comprising a set of one or more serves to enable metadata to be provided to the CDNSP
content servers. The system 116 may comprise at least one control server 118, and
one or more staging servers 120a-n, each of which is typically an HTTP server (e.g.,
Apache). Metadata is provided to the control server 118 by the CDNSP or the content
provider (e.g., using a secure extranet application) and periodically delivered to
the staging servers 120a-n. The staging servers deliver the metadata to the CDN content
servers as necessary.
[0033] The above described content delivery network is merely illustrative. The present
invention may leverage any content delivery infrastructure in which a service provider
operates any type of DNS-based request routing mechanism.
[0034] According to the present invention, a content provider's origin server(s) provide
the Web site's content in the usual manner that would occur in the absence of a content
delivery network (CDN). The origin server(s) may be located at a content provider
location or a third party hosting site. Thus, conventionally, an end user running
a client machine would launch his or her Web browser to a URL identifying the content
provider Web site. Through conventional DNS, the end user's browser would be connected
to the origin server to fetch the content. That well-known operation is augmented
according to the present invention to provide so-called "site insurance," which is
a technique to provide "on-demand" use of the CDN in given circumstances. The CDN
service provider preferably makes the site insurance functionality available to one
or more content provider customers as a managed service, which is available on an
as-needed basis. Thus, according to the invention, Web site traffic is handled by
the origin server(s) in the usual manner (i.e., without the CDN) and is triggered
upon a given occurrence at the origin server. Representative occurrences include,
without limitation, a flash crowd at the site, a site failure, excess traffic to the
site originating from certain geographies or networks, excess demand for certain content
on the site such as high resolution streaming content, excess latency or slowdown
at the site as perceived by network downloading agents deployed throughout the CDN
or elsewhere, a Denial of Service (DoS) attack at or adjacent the site, a DoS attack
that indirectly impacts the site, or the like. Of course, the above examples are merely
illustrative.
[0035] Figure 2 is a simplified block diagram of how site insurance is provided to a particular
origin server 200 by the service provider operating a CDN 202. Origin server 200 has
a name service 204 (e.g., running DNS software such as BIND) associated therewith.
According to the invention, the name service 204 is modified to include a control
mechanism 206 that monitors the server for one or more given occurrences that trigger
the site insurance. Alternatively, control mechanism 206 operates in association with
the CDN name service. In an illustrative embodiment, the control mechanism is implemented
in software executable on a processor and implements a dynamic modification of a local
DNS record (e.g., a DNS A record) upon determining that the given occurrence has taken
place. Thus, the local DNS record may be modified so that a given content provider
domain is directed to a CDN-specific domain, i.e., a domain that cues the CDN's request
routing mechanism 208 to handle the given request. Illustratively, assume that the
normal content provider domain is
www.cp.com and that this is the domain that is used by a given end user browser to fetch content
from the origin server. According to the invention, when the control mechanism 206
identifies the given condition at the site that triggers the site insurance server,
that mechanism rewrites the DNS record in the name service 204 so that
www.cp.com points to a CDN request routing mechanism. Thus, for example, if the CDN domain is
g.cdnsp.net, the domain
www.cp.com is pointed to g.cdnsp.net. A convenient way to do this is to insert a DNS CNAME into
the A record for
www.cp.com. Any other convenient aliasing technique, such as domain delegation, can be used.
As a result of this modification, requests for content associated with the
www.cp.com domain are selectively handled by the CDN.
[0036] Figure 3 is a flowchart of the process for a particular event that triggers the site
insurance. Step 300 assumes the default operation wherein the origin server is operating
without assistance from the CDN. At step 302, a test is made to determine whether
a given event triggering the site "insurance policy" has occurred. If not, the routine
cycles. As noted above, there may be many diverse types of events that could trigger
the insurance. When the given event occurs, as indicated by a positive outcome of
the test at step 302, the routine continues at step 304 wherein the control mechanism
rewrites the local DNS record as described above. This redirects DNS queries, which
were originally intended for the content provider domain, to the CDN domain. At step
306, this rewrite cues the CDNSP's DNS request routing mechanism to resolve the query.
As a consequence, the query (and thus the content request) is managed by the CDN,
thereby relieving the origin server of having to handle the request. At step 308,
a test is made to determine whether the given event that has triggered the insurance
has ended. If not, the routine cycles and the site insurance is maintained. If, however,
the outcome of the test at step 308 indicates that the given event that triggered
the insurance has ended, the routine continues at step 310 to rewrite the local DNS
record (e.g., by removing the CNAME). This returns the site back to its default operation,
wherein the content is delivered without reference to the CDN. Steps 308 and 310 are
not required, as the given site insurance may simply be removed after a given timeout,
at a given time, or upon some other condition.
[0037] The content delivery network service provider may provide the site insurance functionality
as a standalone product or managed service (as described above) or integrated with
a global traffic management (GTM) product or service. An illustrative GTM system is
know commercially as FirstPoint
SM and is available from Akarnai Technologies of Cambridge, Massachusetts. This technique
is described in commonly-owned, copending application Serial No.
09/866,897, filed May 29, 2001, titled Global Load Balancing Across Mirrored Data Centers.
Other commercial available products include Cisco Global Director, global load balancers
from P5, and the like. Any product/system/managed service that has the ability to
direct a client request to one of a set of mirrored sites based on network traffic
conditions, server load, and the like, may be used as the GTM system.
[0038] In this embodiment, the content provider purchases the GTM and the site insurance
services from the CDN service provider. The content provider's origin server may or
may not be mirrored, but typically it will be. Accordingly, the GTM directs end user
requests to the origin server, or to one of the mirrored origin servers, in the usual
manner. Upon occurrence of a given event triggering the insurance policy, however,
the GTM, as modified to include the site insurance mechanism, automatically and seamlessly
moves traffic away from the origin servers and onto the CDN.
[0039] Integrating GTM and site insurance functionality in this manner provides significant
advantages. In low demand situations, the GTM simply directs end users to the origin
servers in the normal manner. As the demand increases, however, the GTM automatically
senses the load changes and directs it to the CDN, where it can be more effectively
managed by the distributed CDN infrastructure.
[0040] Figure 4 illustrates how a customer Web site is integrated into the traffic redirection
system to take advantage of the site insurance. It is assumed that the customer has
a distributed web site of at least two (2) or more mirrored origin servers. Typically,
the GTM system operates to load balance multiple subdomains/properties provided they
are in the same data centers. As described in Serial No. 09/866,897, integration simply
requires that the customer set its authoritative name server 400 to return a CNAME
to the GTM name servers 408, which, thereafter, are used to resolve DNS queries to
the mirrored customer site. Recursion is also disabled at the customer's authoritative
name server. In operation of the GTM system, an end user 402 makes a request to the
mirrored site using a conventional web browser or the like. The end user's local name
server 404 issues a request to the authoritative name server 400 (or to a root server
if needed, which returns data identifying the authoritative name server). The authoritative
name server then returns the name of a name server 408 in the managed service. The
local name server then queries the name server 408 for an IP address. In response,
the name server 408 responds with a set containing one or more IP addresses that are
"optimal" for that given local name server and, thus, for the requesting end user.
As described in 09/866,897, the optimal set of IP addresses may be generated based
on network maps created by testing the performance of representative common points
on the network. The local name server selects an IP address from the "optimal" IP
address list and returns this IP address to the requesting end user client browser.
The browser then connects to that IP address to retrieve the desired content, e.g.,
the home page of the requested site. The above-described operation is augmented according
to the present invention to include the site insurance functionality. The control
mechanism 405 is illustrated in the drawing. Control mechanism 405 monitors for occurrence
of the one or more triggering events to provide the site insurance functionality.
This can be accomplished in a seamless manner by having authoritative name server
400, upon occurrence of the event, simply return the name of whatever lower level
CDN name server will manage the request. The CDN service provider may operate separate
name server mechanisms for the GTM service and for the site insurance, or these functions
can be integrated into the same CDNSP-managed DNS. When the triggering event occurs,
the end user browser's local name server 404 is handed back the name of a CDN name
server from which the local name server 404 obtains the IP address of a CDN edge server.
This redirection occurs automatically and without user involvement or knowledge.
[0041] Representative machines on which the present invention is operated may be Intel Pentium-based
computers running a Linux or Linux-variant operating system and one or more applications
to carry out the described functionality. One or more of the processes described above
are implemented as computer programs, namely, as a set of computer instructions, for
performing the functionality described.
[0042] Having described our invention, what we claim is as follows.
1. A method of protecting an origin server associated with a content provider and a content
provider domain, using a content delivery network (CDN) that comprises a set of content
servers and a CDN domain name server (DNS), the method comprising:
monitoring, using a control mechanism (206) associated with the origin server whether
a given event occurs at the origin server (302);
if the given event occurs: automatically triggering a dynamic modification (304) of
a DNS record in a name server to point to a CDN domain, so that the control mechanism
(206) redirects, to the CDN domain, a DNS query directed to the content provider domain
and associated with given content normally hosted on the origin server;
responsive to an end user's name server making a DNS query to the CDN domain, resolving
(306) the CDN domain to identify an IP address of a specific content server selected
from the set of content servers in the CDN; and
delivering the given content from the identified content server.
2. The method as described in Claim 1 wherein additional DNS queries are redirected to
the CDN domain until it is determined that the given event has ended (308).
3. The method as described in Claim 1 wherein the given content is an object, or a markup
language page having a set of one or more embedded objects.
4. The method as described in Claim 1 wherein the given event is an origin server failure.
5. The method as described in Claim 1 wherein the given event is an occurrence of excess
demand at a site hosted on the origin server.
6. The method as described in Claim 1 wherein the given event is any of: (i) a receipt
of a request for content that cannot be served from the origin server, (ii) excess
demand for streaming content on a Website hosted by the origin server, (iii) excess
traffic originating from a certain geography or network; (iv) excess latency at the
site as perceived by network agents, and (v) a Denial of Service (DOS) attack.
7. The method as described in Claim 1, wherein the CDN further provides a traffic management
service, comprising:
responsive to the end user's name server making a query to the content provider domain,
and when the given event has not occurred, resolving the query to an IP address associated
with an origin server.
8. The method as described in Claim 7, wherein the origin server is one of a set of mirrored
origin servers.
9. The method as described in Claim 1, wherein the dynamic modification of the DNS record
is made in a name server associated with the origin server.
10. The method as described in Claim 1, wherein the dynamic modification of the DNS record
is made in a name server associated with the CDN.
11. The method as described in Claim 1 wherein the DNS record is dynamically modified
using a CNAME.
12. A system for protecting an origin server associated with a content provider and a
content provider domain, using a content delivery network (CDN) that comprises a set
of content servers and a CDN domain name server (DNS), the system comprising:
a control mechanism (206) associated with the origin server that monitors whether
a given event occurs at the origin server (200), and, if the given event occurs, automatically
triggering a dynamic modification of a DNS record in a name server (204) to point
to a CDN domain (202), so that the control mechanism (206) redirects, to the CDN domain
(202), a DNS query directed to the content provider domain and associated with given
content normally hosted on the origin server (200); and
a CDN name server (208) that resolves the CDN domain to identify an IP address of
a specific content server selected from the set of content servers in the CDN;
wherein the identified CDN content server receives an end user request for content
made to the IP address and delivers the given content.
13. The system as described in Claim 12 wherein the name server redirects additional DNS
queries to the CDN domain until it is determined that the given event has ended.
14. The system as described in Claim 12 wherein the given content is an object, or a markup
language page having a set of one or more embedded objects.
15. The system as described in Claim 1 wherein the given event is any of: (i) origin server
failure, (ii) an occurrence of excess demand at a site hosted on the origin server,
(iii) a receipt of a request for content that cannot be served from the origin server,
(iv) excess demand for streaming content on a Website hosted by the origin server,
(v) excess traffic originating from a certain geography or network; (vi) excess latency
at the site as perceived by network agents, and (vii) a Denial of Service (DOS) attack.
16. The system as described in Claim 12, wherein the name server is a name server associated
with the origin server.
17. The system as described in Claim 12, wherein the name server is a CDN name server.
18. The system as described in Claim 12, wherein the name server dynamically modifies
the DNS record using a CNAME.
1. Verfahren zum Schutz eines Ursprungsservers, der mit einem Inhaltsprovider und einer
Inhaltsproviderdomain assoziiert ist, unter Verwendung eines Inhaltsabgabenetzwerks
(CDN), das eine Reihe von Inhaltsservern und einen CDN-Domainnamenserver (DNS) enthält,
wobei das Verfahren Folgendes umfasst:
Überwachung unter Verwendung eines Steuermechanismus (206), der mit dem Ursprungsserver
assoziiert ist, ob ein bestimmtes Ereignis an dem Ursprungsserver (302) auftritt;
wenn das bestimmte Ereignis auftritt: automatisches Triggern einer dynamischen Modifikation
(304) eines DNS-Datensatzes in einem Namenserver, um auf eine CDN-Domain zu verweisen,
so dass der Steuermechanismus (206) eine DNS-Anfrage, die an die Inhaltsproviderdomain
gerichtet ist und die mit einem bestimmten Inhalt assoziiert ist, der normalerweise
auf dem Ursprungsserver gehostet ist, an die CDN-Domain umleitet;
Ausführen einer DNS-Anfrage an die CDN-Domain in Antwort auf einen Endnutzernamenserver,
Auflösung (306) der CDN-Domain, um eine IP-Adresse eines speziellen Inhaltsservers,
ausgewählt aus der Reihe der Inhaltsserver in dem CDN, zu identifizieren; und
Abgabe des bestimmten Inhalts von dem identifizierten Inhaltsserver.
2. Verfahren nach Anspruch 1, wobei zusätzliche DNS-Anfragen an die CDN-Domain zurückgerichtet
werden, bis festgestellt ist, dass das bestimmte Ereignis beendet ist (308).
3. Verfahren nach Anspruch 1, wobei der bestimmte Inhalt ein Objekt ist oder eine Markup-Sprachseite,
die eine Reihe von ein oder mehreren eingebetteten Objekten enthält.
4. Verfahren nach Anspruch 1, wobei das bestimmte Ereignis ein Fehler des Ursprungsservers
ist.
5. Verfahren nach Anspruch 1, wobei das bestimmte Ereignis das Auftreten einer überhöhten
Anforderung an eine Seite ist, die auf dem Ursprungsserver gehostet ist.
6. Verfahren nach Anspruch 1, wobei das bestimmte Ereignis eines des Folgenden ist: (i)
Empfang einer Anforderung von Inhalt, der nicht von dem Ursprungsserver bedient werden
kann, (ii) übermäßige Anforderung zum Streamen vom Inhalt einer Webseite, die auf
dem Ursprungsserver gehostet ist, (iii) übermäßiger Verkehr, der von einer bestimmten
Geografie oder einem bestimmten Netzwerk stammt, (iv) übermäßige Latenz auf der Seite,
welche von Netzwerkagenten festgestellt wird, und (v) ein Denial of Service (DOS)-Angriff.
7. Verfahren nach Anspruch 1, wobei das CDN ferner einen Verkehrsmanagementdienst aufweist,
der Folgendes umfasst:
Ausführen einer Anfrage an die Inhaltsproviderdomain in Antwort auf den Namenserver
des Endusers, und, wenn das bestimmte Ereignis nicht aufgetreten ist, Auflösen der
Anfrage an eine IP-Adresse, die mit dem Ursprungsserver assoziiert ist.
8. Verfahren nach Anspruch 7, wobei der Ursprungsserver einer einer Reihe von gespiegelten
Ursprungsservern ist.
9. Verfahren nach Anspruch 1, wobei die dynamische Modifikation des DNS-Datensatzes in
einem Namenserver ausgeführt ist, der mit dem Ursprungsserver assoziiert ist.
10. Verfahren nach Anspruch 1, wobei die dynamische Modifikation des DNS-Datensatzes in
einem Namenserver ausgeführt wird, der mit dem CDN assoziiert ist.
11. Verfahren nach Anspruch 1, wobei der DNS-Datensatz dynamisch unter Verwendung eines
CNAME modifiziert wird.
12. System zum Schutz eines Ursprungsservers, der mit einem Inhaltsprovider und einer
Inhaltsproviderdomain assoziiert ist, unter Verwendung eines Inhaltsabgabenetzwerks
(CDN), welches einen Satz von Inhaltsservern und einen CDN-Domainnamenserver (DNS)
enthält, wobei das System Folgendes umfasst:
einen Steuermechanismus (206), der mit dem Ursprungsserver assoziiert ist, der überwacht,
ob ein gegebenes Ereignis an dem Ursprungsserver (200) auftritt, und, wenn das Ereignis
auftritt, automatisches Triggern einer dynamischen Modifikation eines DNS-Datensatzes
in einem Namenserver (204), um auf eine CDN-Domain (202) zu verweisen, so dass der
Steuermechanismus (206) eine DNS-Anfrage, die an die Inhaltsproviderdomain gerichtet
ist und mit einem bestimmten Inhalt assoziiert ist, der normalerweise an dem Ursprungsserver
(200) gehostet wird, auf die CDN-Domain (202) richtet; und
einen CDN-Namenserver (208), der die CDN-Domain auflöst, um eine IP-Adresse eines
bestimmten Inhaltsservers zu identifizieren, der aus der Reihe von Inhaltsservern
im CDN ausgewählt ist,
wobei der identifizierte CDN-Inhaltsserver eine Endnutzeranfrage auf Inhalt empfängt,
die an die IP-Adresse gerichtet ist und den bestimmten Inhalt abgibt.
13. System nach Anspruch 12, wobei der Namenserver zusätzliche DNS-Anfragen an die CDN-Domain
umleitet, bis festgestellt ist, dass das bestimmte Ereignis beendet ist.
14. System nach Anspruch 12, wobei der bestimmte Inhalt ein Objekt oder eine Markup-Sprachseite
ist, die einen Satz von ein oder mehreren eingebetteten Objekten enthält.
15. System nach Anspruch 1, wobei das bestimmte Ereignis eines des Folgenden ist: (i)
Ursprungsserverfehler, (ii) Auftreten von übermäßiger Anfrage auf einer Seite, die
an dem Ursprungsserver gehostet ist, (iii) Empfang einer Anfrage für Inhalt, der nicht
von dem Ursprungsserver bedient werden kann, (iv) übermäßige Anfrage zum Streamen
vom Inhalt auf einer Webseite, die auf dem Ursprungsserver gehostet ist, (v) übermäßiger
Verkehr, der von einer bestimmten Geografie oder einem bestimmten Netzwerk stammt,
(vi) übermäßige Latenz an der Seite, wie es von Netzwerkagenten festgestellt wird,
und (vii) ein Denial of Service (DOS)-Angriff.
16. System nach Anspruch 12, wobei der Namenserver ein Namenserver ist, der mit dem Ursprungsserver
assoziiert ist.
17. System nach Anspruch 12, wobei der Namenserver ein CDN-Namenserver ist.
18. System nach Anspruch 12, wobei der Namenserver den DNS-Datensatz unter Verwendung
eines CNAME dynamisch ändert.
1. Procédé de protection d'un serveur d'origine associé à un fournisseur de contenu et
à un domaine de fournisseur de contenu, en utilisant un réseau de distribution de
contenu (CDN) qui comprend un ensemble de serveurs de contenu et un serveur de noms
de domaine de réseau CDN (DNS), le procédé comprenant :
le fait de contrôler, en utilisant un mécanisme de contrôle (206) associé au serveur
d'origine, si un événement donné se produit au niveau du serveur d'origine (302) ;
si l'événement donné se produit : le déclenchement automatique d'une modification
dynamique (304) d'un enregistrement de serveur DNS dans un serveur de noms, en vue
de pointer vers un domaine de réseau CDN, de sorte que le mécanisme de contrôle (206)
réoriente, vers le domaine de réseau CDN, une demande de serveur DNS orientée vers
le domaine de fournisseur de contenu et associée à un contenu donné normalement hébergé
sur le serveur d'origine ;
en réponse à l'émission, par un serveur de noms de l'utilisateur final, d'une demande
de serveur DNS vers le domaine de réseau CDN, la résolution (306) du domaine de réseau
CDN en vue d'identifier une adresse IP d'un serveur de contenu spécifique sélectionné
à partir de l'ensemble de serveurs de contenu dans le réseau CDN ; et
la distribution du contenu donné à partir du serveur de contenu identifié.
2. Procédé selon la revendication 1, dans lequel les demandes de serveur DNS supplémentaires
sont réorientées vers le domaine de réseau CDN jusqu'à ce qu'il soit déterminé que
l'événement donné a pris fin (308).
3. Procédé selon la revendication 1, dans lequel le contenu donné est un objet, ou une
page de langage de balisage comportant un ensemble d'un ou plusieurs objets intégrés.
4. Procédé selon la revendication 1, dans lequel l'événement donné est un dysfonctionnement
de serveur d'origine.
5. Procédé selon la revendication 1, dans lequel l'événement donné est l'occurrence d'une
demande en excès au niveau d'un site hébergé sur le serveur d'origine.
6. Procédé selon la revendication 1, dans lequel l'événement donné est l'un quelconque
de : (i) une réception d'une demande de contenu qui ne peut être desservie à partir
du serveur d'origine ; (ii) une demande en excès pour la diffusion de contenu sur
un site web hébergé par le serveur d'origine ; (iii) un trafic en excès provenant
d'une certaine zone géographique ou d'un certain réseau ; (iv) une latence en excès
au niveau du site telle que perçue par des agents de réseau ; et (v) une attaque par
déni de service (DOS).
7. Procédé selon la revendication 1, dans lequel le réseau CDN offre en outre un service
de gestion du trafic, comprenant :
en réponse à l'émission, par le serveur de noms de l'utilisateur final, d'une demande
au domaine de fournisseur de contenu, et lorsque l'événement donné ne s'est pas produit,
la résolution de la demande sur une adresse IP associée à un serveur d'origine.
8. Procédé selon la revendication 7, dans lequel le serveur d'origine est l'un d'un ensemble
de serveurs d'origine mis en miroir.
9. Procédé selon la revendication 1, dans lequel la modification dynamique de l'enregistrement
de serveur DNS est mise en oeuvre dans un serveur de noms associé au serveur d'origine.
10. Procédé selon la revendication 1, dans lequel la modification dynamique de l'enregistrement
de serveur DNS est mise en oeuvre dans un serveur de noms associé au réseau CDN.
11. Procédé selon la revendication 1, dans lequel l'enregistrement de serveur DNS est
modifié dynamiquement en utilisant un enregistrement CNAME.
12. Système destiné à protéger un serveur d'origine associé à un fournisseur de contenu
et à un domaine de fournisseur de contenu, en utilisant un réseau de distribution
de contenu (CDN) qui comporte un ensemble de serveurs de contenu et un serveur de
noms de domaine de réseau CDN (DNS), le système comprenant :
un mécanisme de contrôle (206) associé au serveur d'origine, lequel contrôle si un
événement donné se produit au niveau du serveur d'origine (200), et, si l'événement
donné se produit, déclenche automatiquement une modification dynamique d'un enregistrement
de serveur DNS dans un serveur de noms (204) en vue de pointer vers un domaine de
réseau CDN (202), de sorte que le mécanisme de contrôle (206) réoriente, vers le domaine
de réseau CDN (202), une demande de serveur DNS orientée vers le domaine de fournisseur
de contenu et associée à un contenu donné normalement hébergé sur le serveur d'origine
(200) ; et
un serveur de noms de réseau CDN (208) qui résout le domaine de réseau CDN en vue
d'identifier une adresse IP d'un serveur de contenu spécifique sélectionné à partir
de l'ensemble de serveurs de contenu dans le réseau CDN ;
dans lequel le serveur de contenu de réseau CDN identifié reçoit une demande de contenu
d'utilisateur final émise vers l'adresse IP et fournit le contenu donné.
13. Système selon la revendication 12, dans lequel le serveur de noms réoriente les demandes
de serveur DNS supplémentaires vers le domaine de réseau CDN jusqu'à ce qu'il soit
déterminé que l'événement donné a pris fin.
14. Système selon la revendication 12, dans lequel le contenu donné est un objet, ou une
page de langage de balisage comportant un ensemble d'un ou plusieurs objets intégrés.
15. Système selon la revendication 1, dans lequel l'événement donné est l'un quelconque
de : (i) un dysfonctionnement de serveur d'origine ; (ii) l'occurrence d'une demande
en excès au niveau d'un site hébergé sur le serveur d'origine ; (iii) une réception
d'une demande de contenu qui ne peut être desservie à partir du serveur d'origine
; (iv) une demande en excès pour la diffusion de contenu sur un site web hébergé par
le serveur d'origine ; (v) un trafic en excès provenant d'une certaine zone géographique
ou d'un certain réseau ; (vi) une latence en excès au niveau du site telle que perçue
par des agents de réseau ; et (vii) une attaque par déni de service (DOS).
16. Système selon la revendication 12, dans lequel le serveur de noms est un serveur de
noms associé au serveur d'origine.
17. Système selon la revendication 12, dans lequel le serveur de noms est un serveur de
noms de réseau CDN.
18. Système selon la revendication 12, dans lequel le serveur de noms modifie dynamiquement
l'enregistrement de serveur DNS en utilisant un enregistrement CNAME .